From df3632c655959811b648ed362124b5a9def58eb3 Mon Sep 17 00:00:00 2001 From: cyrinenajar <105717163+cyrinenajar@users.noreply.github.com> Date: Fri, 9 Dec 2022 13:55:18 +0000 Subject: [PATCH] Enable Dependency reviewer --- .github/workflows/dependency_enforcement.yml | 21 ++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 .github/workflows/dependency_enforcement.yml diff --git a/.github/workflows/dependency_enforcement.yml b/.github/workflows/dependency_enforcement.yml new file mode 100644 index 0000000..4dd319c --- /dev/null +++ b/.github/workflows/dependency_enforcement.yml @@ -0,0 +1,21 @@ +# For most projects, this workflow file will not need changing; you simply need +# to commit it to your repository. +# +# Reach out on Slack at '#secrity-support' to get help. +# Link to the action: https://github.com/actions/dependency-review-action + +name: "Dependency Review" +on: [pull_request] +permissions: + contents: read +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - name: "Checkout Repository" + uses: actions/checkout@v3 + - name: Dependency Review + uses: actions/dependency-review-action@v3 + with: + fail-on-severity: critical + \ No newline at end of file